Debian Security Update DSA-4686 apache-log4j1.2 - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,885
Reaction score
74
Credits
-1,257
It was discovered that the SocketServer class included in apache-log4j1.2, a logging library for java, is vulnerable to deserialization of untrusted data. An attacker can take advantage of this flaw to execute arbitrary code in the context of the logger application by sending a specially crafted log event.

Continue reading...
 


Follow Linux.org

Staff online


Latest posts

Top